Privacy Policy | MODENU
Your data, explained

Privacy Policy

📅 Last updated: July 9, 2026 ✍️ Published by MODENU Editorial Team ⏱️ 5–10 min read
MODENU respects your privacy. This Privacy Policy explains what personal information we collect on modenu.com, why we collect it, who we share it with and how you can exercise your rights under GDPR, CCPA and other applicable laws.

Who is the data controller

The data controller for personal information collected on modenu.com is the operator of the MODENU project, contactable at [email protected]. If applicable law requires a designated representative, one will be appointed and named on this page.

Information we collect

We collect three broad categories of data:

1. Information you give us

Email address, message content and any voluntary attachments when you write to us, subscribe to a newsletter, or complete our contact form.

2. Information collected automatically

Browser type and version, operating system, referring URL, pages visited, timestamps, general geographic location derived from IP, and an anonymised device identifier used for analytics and fraud prevention. IP addresses are truncated before being written to our logs.

3. Information collected by advertising partners

Ad networks such as Google, Ezoic or Media.net may set cookies or similar identifiers to serve and measure advertising. See the Cookie Policy for the full list.

Why we collect it

  • To operate the site — serving pages, load-balancing, fraud prevention, security.
  • To reply to you — answering your emails and contact requests.
  • To measure and improve — anonymised analytics tell us which reviews are useful and which need work.
  • To fund the site — serving advertising, subject to your consent where required by law.
  • To comply with legal obligations — tax, accounting, responding to lawful requests from authorities.

Legal bases (GDPR)

For readers in the European Economic Area, the United Kingdom and Switzerland, we rely on the following GDPR legal bases: consent (for non-essential cookies and marketing), legitimate interest (for site security, aggregate analytics and fraud prevention), contractual necessity (to reply to your inquiries) and legal obligation (to keep tax and accounting records).

Data sharing & processors

We share data only with vetted processors that help us run the site: our hosting provider, our email provider, our analytics provider and our advertising partners. All processors are bound by contractual privacy obligations and process data on our instructions.

We do not sell personal information. Under the CCPA, this constitutes a “do not sell” posture by default.

International transfers

Some processors are located outside your country of residence, including in the United States. Where required, transfers rely on Standard Contractual Clauses (SCCs) or an equivalent transfer mechanism.

Retention

Contact messages are retained for up to 24 months after our last interaction with you. Analytics data is retained in aggregated, anonymised form for up to 26 months. Ad-network data is subject to each partner’s own retention rules.

Your rights

Subject to applicable law you have the right to: access your data, correct inaccurate data, delete data, restrict or object to processing, port your data, and lodge a complaint with a supervisory authority. To exercise a right, write to [email protected]. We reply within 30 days and never charge a fee unless a request is manifestly unfounded or excessive.

Children

MODENU is not directed at children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us for prompt deletion.

Changes

We may update this Privacy Policy. When we do, the Last updated date at the top will change. Material changes will be highlighted at the top of the page for at least 30 days.

Security measures

Reasonable technical and organisational measures protect the personal information we collect. These include TLS encryption for all traffic, encrypted storage of contact-message attachments, restricted-access administrative dashboards protected by two-factor authentication, IP-truncation of server logs and quarterly review of processor security posture.

No system is perfectly secure. If we ever suffer a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users and the appropriate supervisory authority in line with applicable law (typically within 72 hours under GDPR).

California, Virginia & other US-state rights

Residents of California (CCPA/CPRA), Virginia, Colorado, Connecticut, Utah and other US states with comparable laws have specific rights, including the right to know what information is collected, the right to delete, the right to correct and the right to opt out of the sale or sharing of personal information. As stated above, we do not sell personal information. To exercise any state-law right, write to [email protected] and identify the state you reside in.

Frequently Asked Questions

Do you sell my data?

No. We do not sell personal information. Under the CCPA and similar laws, this is our default posture.

How do I opt out of tracking cookies?

Use the consent banner shown on your first visit, or clear your browser cookies for our domain. Details are in the Cookie Policy.

How do I delete my data?

Write to [email protected] with the email address you contacted us from. We will confirm identity and delete records within 30 days.

Questions about this policy?
Our team reads every message and typically replies within 48 hours.
Contact Us →